A long road ahead for Direct & Digital Marketing under the General Data Protection Regulation (GDPR)

As a Data Protection Officer, one of the most common questions I am often asked by our customers and at networking events is, what are the impacts of GDPR on Marketing?
Historically, the way we have obtained consent to personal information within digital and direct marketing has often been a grey area. The Data Protection Act 1998 was predicated around the Data Protection Directive (DPD), established well over 21 years ago. It could not have possibly predicted, or have catered for the digital age where big data has become big business. The premise of organisations getting as much data as they can, then figuring out how to process, profile and analyse that data in order to get as much value out of it has been marketing best practise for some time. Marketers have also invented clever ways to obtain your personal information, such as tradeshows where your badge is scanned and your information stored. Or, tempting you with a competition to win the latest gadget and all that is required is your business card. You often see companies posting interesting white papers online but you have to fill in your details to obtain a copy. These techniques have been around for years and all help marketers analyse and profile information so that they can identify you or your organisation’s interests, so that they can target you for future products and services or campaigns.
This is not to say it has been open season for marketers under the DPD. Recently, there have been a number of cases where Marketing companies have fallen foul of the legislation and the Information Commissioner’s Office (ICO) have imposed fines. For instance, one organisation was fined £140,000.00 for sending 4.4M spam texts. Another organisation making nuisance phone calls was fined £80,000. However, fines under the DPA are not effective or dissuasive as the ICO can only fine up to £500,000 as a maximum. This is now all about to change under the GDPR.
GDPR sets out six principles in the regulation. These form the rules on how data is to be treated (Article 5). These principles ensure that the processing of data is done lawfully and fairly, is collected for explicit legitimate purposes whilst making sure the data is adequate, accurate, and retained for only as long as necessary. The data must also be processed in a manner that maintains the integrity and confidentiality of the personal data.
The Information Commissioner (ICO) is currently defining guidance for organisations on how to apply with GDPR – see the current guidance for marketers on GDPR.
Where marketing is concerned this completely changes the way we think about handling data. Direct marketers will need to demonstrate how their organisation meets the lawful conditions. If an organisation cannot prove how they have obtained consent the likelihood is that they will be fined. Marketers must align themselves with the GDPR principles. The collection of data needs to be relevant for the purpose. This means if you have run a campaign or competition you can only use the information for that purpose. Creating another purpose to use that information will need further consent from the data subject. This is bad news for marketing as a common practice has been to grow your databases using these methods.


